Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 197

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Global central bankers unite in defense of Fed Chair Jerome Powell
Pentagon is embracing Musk's Grok AI chatbot as it draws global outcry
Buy this social media stock with lots of upside thanks to AI, says Evercore ISI
Salesforce releases updated Slackbot powered by Anthropic's AI model
India’s exports to China surge in December while shipments to U.S. decline as Trump tariffs bite
Australia banned social media for under 16s a month ago — here's how it's going
Coinbase CEO says key crypto vote can be rescheduled after 11th hour cancellation
This Korean retail giant has been under pressure. Deutsche Bank thinks the bad news is baked in
Trump's proposed ban on buying single-family homes introduces uncertainty for family offices
Stocks making the biggest moves premarket: PNC, ImmunityBio, Coupang & more